Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
sql injection vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2014-2081
Multiple SQL injection vulnerabilities in the login in web_reports/cgi-bin/InfoStation.cgi in Innovative vtls-Virtua prior to 2013.2.4 and 2014.x prior to 2014.1.1 allow remote malicious users to execute arbitrary SQL commands via the (1) username or (2) password parameter.
Iii Vtls-virtua 2013.2.3
Iii Vtls-virtua 2014.1.0
1 EDB exploit
NA
CVE-2013-6058
SQL injection vulnerability in appRain CMF 3.0.2 and previous versions allows remote malicious users to execute arbitrary SQL commands via the PATH_INFO to blog-by-cat/.
Apprain Apprain 3.0.1
Apprain Apprain 0.1.1
Apprain Apprain 0.1.5
Apprain Apprain 0.1.2
Apprain Apprain 0.1.0
Apprain Apprain
Apprain Apprain 0.1.3
Apprain Apprain 0.2.1.1
Apprain Apprain 0.1.4
1 EDB exploit
5.3
CVSSv3
CVE-2019-14430
plugin/Audit/Objects/AuditTable.php in YouPHPTube up to and including 7.2 allows SQL Injection.
Youphptube Youphptube
1 EDB exploit
7.2
CVSSv3
CVE-2017-6088
Multiple SQL injection vulnerabilities in EyesOfNetwork (aka EON) 5.0 and previous versions allow remote authenticated users to execute arbitrary SQL commands via the (1) bp_name, (2) display, (3) search, or (4) equipment parameter to module/monitoring_ged/ged_functions.php or th...
Eyesofnetwork Eyesofnetwork
1 EDB exploit
9.8
CVSSv3
CVE-2017-17999
SQL injection vulnerability in RISE Ultimate Project Manager 1.9 allows remote malicious users to execute arbitrary SQL commands via the search parameter to index.php/knowledge_base/get_article_suggestion/.
Fairsketch Rise Ultimate Project Manager 1.9
1 EDB exploit
9.8
CVSSv3
CVE-2018-7474
An issue exists in Textpattern CMS 4.6.2 and previous versions. It is possible to inject SQL code in the variable "qty" on the page index.php.
Textpattern Textpattern
1 EDB exploit
NA
CVE-2009-3804
Multiple SQL injection vulnerabilities in modules/forum/post.php in RunCMS 2M1 allow remote authenticated users to execute arbitrary SQL commands via (1) the pid parameter, which is not properly handled by the store function in modules/forum/class/class.forumposts.php, or (2) the...
Runcms Runcms 2m1
2 EDB exploits
NA
CVE-2013-6839
SQL injection vulnerability in InstantSoft InstantCMS 1.10.3 and previous versions allows remote malicious users to execute arbitrary SQL commands via the orderby parameter to catalog/[id].
Instantsoft Instantcms
1 EDB exploit
NA
CVE-2010-1583
SQL injection vulnerability in the loadByKey function in the TznDbConnection class in tzn_mysql.php in Tirzen (aka TZN) Framework 1.5, as used in TaskFreak! prior to 0.6.3, allows remote malicious users to execute arbitrary SQL commands via the username field in a login action.
Taskfreak Taskfreak! 0.4.0
Taskfreak Taskfreak! 0.6.0
Taskfreak Taskfreak! 0.5.5
Taskfreak Taskfreak! 0.1.4
Taskfreak Taskfreak! 0.5.1
Taskfreak Taskfreak!
Taskfreak Taskfreak! 0.4.2
Taskfreak Taskfreak! 0.6.1
Taskfreak Taskfreak! 0.5.2
Taskfreak Taskfreak! 0.5.3
Taskfreak Taskfreak! 0.5.0
Taskfreak Taskfreak! 0.5.4
Taskfreak Taskfreak! 0.1.2
Taskfreak Taskfreak! 0.5.6
Taskfreak Taskfreak! 0.4.1
Taskfreak Taskfreak! 0.1
Taskfreak Taskfreak! 0.1.3
Taskfreak Taskfreak! 0.5.7
Tirzen Tirzen Framework 1.5
1 EDB exploit
9.8
CVSSv3
CVE-2015-3933
Multiple SQL injection vulnerabilities in inc/lib/User.class.php in MetalGenix GeniXCMS prior to 0.0.3-patch allow remote malicious users to execute arbitrary SQL commands via the (1) email parameter or (2) userid parameter to register.php.
Metalgenix Genixcms
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-28995
CVE-2024-36680
CVE-2024-35537
unauthorized
CVE-2024-21518
CVE-2024-37673
cross-site scripting
SSRF
CVE-2024-6241
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
3
4
5
6
7
8
9
10
NEXT »